Getting Data In

SC4S not able to parse syslog and ingest

wayne333
Engager

I've set up my SC4S and connected to my indexer. Logs are ingested as show below but further down, those does not get ingested, I see them while im listening with tcpdump. What have I missed?

Ingested

<174>2025-08-27T10:46:46.743660+08:00 idrac-xxxxxxxxxx1 Severity: Informational, Category: Audit, MessageID: USR0031, Message: Unable to log in for root from xxx.xxx.xx.32 using GUI

 

Not ingested

<190>Aug 27 09:59:52 xxxxxxxxO-DSSW6605 raslogd: AUDIT, 2025/08/27-09:59:52 (+08), [SNMP-3020], INFO, SECURITY, NONE/admin/xxx.xxx.xx.153/snmp/snmp,NA/xxxxxxxxO-DSSW6605/FID 128, 9.2.2, , , , , , , Event: Login, Info: SNMP login attempt via IP: xxx.xxx.xx.153, Last accessed user: , Success count: 0, Failure count: 1292, Time: Wed Aug 27 09:59:48 2025

<174>Aug 27 11:12:01 xxxxxxxxo-xxxxx1 hsm[4519]: info : 0 : Command: sysconf time 11:13 20250827 : admin : xxx.xxx.xx.32/57827
11:13:00.706364 veth0 Out IP xxx.xxx.xx.170.57454 > 1x.xx.x.8.514: SYSLOG local5.info, length: 125

 

 

Labels (2)
0 Karma

livehybrid
SplunkTrust
SplunkTrust

Hi @wayne333 
Are you able to confirm that these events haven’t been indexed into a fallback index incase they weren’t properly typed by SC4S?

 

 

🌟 Did this answer help you? If so, please consider:

    • Adding karma to show it was useful
    • Marking it as the solution if it resolved your issue
    • Commenting if you need any clarification

Your feedback encourages the volunteers in this community to continue contributing.

0 Karma

wayne333
Engager

Hi @livehybrid,
Thanks for your time.


Yes , have checked the other default SC4S indexes as well. These 2 products with the same format of logs. The logs provided are from Brocade and Thales which are also known vendors in SC4S. 

Did I miss anything other than listening to the port in the env file?

 

0 Karma
Get Updates on the Splunk Community!

Splunk Search APIを使えば調査過程が残せます

   このゲストブログは、JCOM株式会社の情報セキュリティ本部・専任部長である渡辺慎太郎氏によって執筆されました。 Note: This article is published in both Japanese ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...